Skip to content

CorrespondArt

Privacy Policy

Effective August 8, 2026

CorrespondArt is a small personal project — a way to give a physical art card a digital life. It is not a company, and this is not a lawyer’s document. It’s a plain-language, honest account of what the site stores about you, why, and who can see it. If anything here is unclear, email [email protected] and we’ll explain it.

01What we collect

Here is everything the site keeps about you:

  • Your account. The email address you sign in with, and a display name (we default it from your email; you can change it in settings).
  • Cards you make. The card’s title, its written note / page content, its status, and its share settings.
  • Photos you upload. We re-encode every photo into web-sized copies and discard the original file. The copies we serve carry no embedded metadata (see Photo location & time below for the one exception).
  • Journey events. As a card is created, sent, and received, we record those steps — including the city/region text shown on each postmark.
  • Card passwords. If you put a password on a card, we store it (see Who can see your cards).

There’s no other hidden collection. We do not ask for or store payment details, phone numbers, or contacts.

02Why we collect it

Only to make the thing work. Your email is how you sign in and how we send the handful of notifications tied to your cards. Card content, photos, and journey events are the product — they’re what a card’s page shows. We don’t build advertising or marketing profiles, and we never sell or share your data with anyone for their own purposes.

03Cookies

We set exactly two kinds of cookie, and both are strictly functional — the site can’t work without them:

  • A session cookie once you sign in, so we know it’s you on the next page. It’s HttpOnly (JavaScript can’t read it), and it lasts about 30 days.
  • A per-card password cookie after you correctly enter a card’s password, so you don’t have to retype it every visit. It stores a one-way hash (SHA-256) of the password, not the password itself, is HttpOnly, and lasts about 30 days.

Because neither cookie is used for analytics, advertising, or tracking — only for signing in and unlocking cards you already have the password to — there’s nothing to consent to, so there’s no cookie banner.

04Who can see your cards

Every card has a share setting you control: private (only you and the recipient), photos only (anyone with the link can see the photos), or everything (anyone with the link can see the whole page). You can also add a password, which gates access even for people who have the link. Here is the honest part about those passwords: they are stored in plaintext, on purpose. That’s a deliberate choice — the threat model is low, and the sender needs to be able to read the password back so they can write it on the physical card by hand. So do not treat a card password as secure the way an account password would be.

Because card passwords are stored as-is, never reuse a real password (your email, bank, anything) as a card password. Pick something you’re happy to write on a postcard.

05Photo location & time

The photo copies we serve are stripped of embedded metadata, so no one downloading them gets your camera or location data that way. But before we strip it, we read two things out of each photo’s EXIF and store them on the card: when the photo was taken and, if present, the GPS coordinates where it was taken. These are shown on the card page alongside the photo, so anyone allowed to view that photo can see roughly where and when it was taken.

Most uploads don’t include this data at all. If yours does and you’d rather not share a location, strip the photo’s location before uploading, or keep the card private.

06How long we keep it

We keep your cards, photos, and account for as long as you keep them. Deleting a card removes that card’s photos from disk along with it.

There is currently no self-service account deletion — you can’t delete your whole account from a settings button yet. If you want your account and everything in it removed, email [email protected] and we’ll do it for you.

07Who else touches your data

Just one outside service: Resend, which delivers our email — the sign-in links and the few card notifications. Your email address passes through them for that delivery.

The site itself runs on a single self-hosted server. There is no analytics, no advertising, no tracking, and no third-party scripts of any kind — the pages load only our own code and self-hosted fonts. That’s a feature, not an accident.

08An old feature we retired

Before August 2026, CorrespondArt had an address-matching feature that asked some people for a mailing address to help connect a scanned card to an account. That feature is gone: we no longer collect or use mailing addresses. A few historical records from it may still exist in the database for older accounts. If you’d like yours removed, email us (below) and we’ll clear them.

09Your say

It’s your data. If you want to see what we hold about you, correct something, or have it deleted, just email [email protected] and we’ll sort it out. No forms, no hoops.

10Changes to this policy

If we change how any of this works, we’ll update this page and move the effective date at the top. There’s no version history to dig through — what’s here is what’s true today.


Questions? Write to [email protected].